GDPR Compliance
Last Updated: May 3, 2026
1. Data Controller Information
Unolabs Limited and Unolabs Technologies Pvt Ltd act as Data Controller and Data Processor respectively under the General Data Protection Regulation (GDPR). Our commitment is to ensure that your personal data is processed lawfully, fairly, and in a transparent manner. For any GDPR-related concerns, you can reach our Data Protection Officer at dpo@unolabs.com.
2. Your Rights Under GDPR
As a data subject within the European Economic Area (EEA), you have the following detailed rights: • The Right to be Informed: You have the right to know how your data is being used. • The Right of Access: You can request a copy of the personal data we hold about you. • The Right to Rectification: You can ask us to correct inaccurate or incomplete data. • The Right to Erasure: Also known as 'the right to be forgotten', you can request that we delete your data under certain conditions. • The Right to Restrict Processing: You can ask us to limit how we use your data. • The Right to Data Portability: You have the right to receive your data in a structured, commonly used, and machine-readable format. • The Right to Object: You can object to our processing of your data in certain circumstances, such as for direct marketing.
3. Lawful Basis for Processing
Unolabs processes your personal data based on one or more of the following legal grounds: • Consent: You have given clear consent for us to process your personal data for a specific purpose. • Contract: The processing is necessary for a contract you have with us. • Legal Obligation: The processing is necessary for us to comply with the law. • Legitimate Interests: The processing is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests do not override your fundamental rights.
4. Data Retention and Deletion
We will only keep your personal data for as long as it is necessary for the purposes for which it was collected, as described in this policy. When the data is no longer needed, it will be securely deleted or anonymized so that it can no longer be linked to you. Standard retention periods for client data are typically 7 years unless otherwise required by contract or law.
5. International Data Transfers
If we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented: • Transferring your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. • Using specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
6. Data Breach Notification
In the unlikely event of a data breach, Unolabs will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where the breach is likely to result in a risk to the rights and freedoms of individuals. We will also notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
7. Contact and Supervisory Authority
If you believe that our processing of your personal data infringes GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.